
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47479 is an uncontrolled resource consumption vulnerability in NVIDIA Triton Inference Server for Linux that allows unauthenticated remote attackers to trigger denial of service. It affects all versions from 0.0 through 26.04 of the Triton Inference Server on Linux. The vulnerability was published on July 14, 2026, by NVIDIA Corporation and added to the GitHub Advisory Database the same day. It carries a CVSS v3.1 base score of 7.5 (High), assigned by NVIDIA (GitHub Advisory, Feedly).
The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption), meaning the server fails to properly control the allocation and maintenance of limited resources when processing attacker-supplied input. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially automatable — a characteristic confirmed by CISA's SSVC assessment. The specific mechanism by which resource exhaustion is triggered (e.g., malformed inference requests, excessive connection handling) has not been publicly detailed in available advisories. No public proof-of-concept code has been identified (GitHub Advisory, Feedly).
Successful exploitation results in a denial of service condition, rendering the Triton Inference Server unavailable to legitimate users and applications. The impact is limited to availability — there is no confidentiality or integrity impact, meaning attackers cannot access or modify data through this vulnerability. In production AI/ML inference environments, service disruption could halt dependent workloads, pipelines, or real-time inference applications relying on the server (GitHub Advisory, Feedly).
NVIDIA has released a patch addressing this vulnerability; users should upgrade NVIDIA Triton Inference Server to a version beyond 26.04 as indicated in the advisory. As an immediate workaround, implement network-level access controls (firewalls, security groups) to restrict connections to the Triton Inference Server to trusted IP ranges only, reducing the attack surface for unauthenticated network attackers. Additionally, monitor resource utilization metrics for anomalous consumption patterns and consider rate-limiting inbound requests to the server (GitHub Advisory, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."